Hey all,
We're getting ready to implement JAMF Pro later this month. (I've used AirWatch the past few years.) I've got a best practices question regarding enabling/disabling pairing in the DEP profile. Basic question is, do you allow it or no? Currently we allow it for staff assigned iPhones but disallow it on iPads across the board.
Context here is we previously had a lot of 1:1 devices that went home with students, so I had pairing disabled to try to mitigate jailbreaking attempts and general tomfoolery that students sometimes get into ("I synced my iPad at home and lost all my school apps/data"). Restricting it was never a showstopper but once in a while we need to pair with iTunes to get files off the device or load files into a specific app (example, one special needs app would only load files via itunes. Couldn't get it to use airdrop or other methods). Now we mainly are using cart devices and have some 1:1 staff iPads with very few going home with students. I feel like jailbreaking is less of an issue the past couple years but maybe I'm out of the loop. I'm thinking that relaxing this security setting on iPads for user convenience would not be too disastrous. I'm wondering what you chose to do?
Ideally we'd just disable pairing across the board and enable it on a case by case basis but as I understand it since this setting is managed at the DEP profile level it requires a full reset and reenroll to change it. By the time the need to pair a device arises it's too late to change the setting. I had hopes that having a matching Configurator 2 supervision identity would allow "pairing restricted" iPads to pair with our tech staff's configurator stations for troubleshooting, passcode clearing, etc but haven't been able to get that to work consistently.
Thanks in advance!
Jason
